Field-Level Access Control Flaw in Payload CMS
CVE-2026-105855

7.6HIGH

Key Information:

Vendor

Payloadcms

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105855?

A significant security issue exists in Payload, an open-source headless content management system, where the server does not adequately enforce restrictions on field-level access to the password field within the authentication collection. This flaw affects all versions of Payload prior to 3.90.0 and canary versions prior to 4.0.0-canary.34. The vulnerability enables unauthorized users to potentially modify authentication credentials, leading to serious implications for data security. This issue has been addressed in the latest updates, ensuring improved access control mechanisms are in place.

Affected Version(s)

payload < 3.90.0 < 3.90.0

payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.